US9106635B2

System and method for connecting client devices to a network

Summary by NHIP

Out-of-band TLS Authorization

The method enables client devices to connect to a network by using an out-of-band authorization code within a modified transport layer security session. The code multiplies a negotiated elliptic curve point to generate a pre master secret from the product's x-coordinate, replacing standard key derivation steps.

Claim Score by NHIP

Read claim 17, the broadest

Abstract

A system and method are provided for enabling a client device to connect to a network. The method comprises: obtaining an authorization code via a communication channel different from the network, the authorization code corresponding to the client device; and after detecting initiation of a security negotiation protocol by the client device, using the authorization code in at least one security negotiation operation.

US9106635B2, drawing sheet 1
Sheet 1 of 15

Term

6.6 yearsleft in the term

Expires 21 April 2033, including 96 days of term adjustment.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

23 claims: 9 independent, 14 dependent

  1. 1
    A method of enabling a client device to connect to a network, the method comprising:obtaining, at a server device and from the client device, an authorization code via an out-of-band communication channel different from the network, the authorization code corresponding to the client device;and after detecting initiation of a security negotiation protocol by the client device, using the authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  2. 9
    A method of connecting a client device to a network, the method comprising:initiating, at the client device, a security negotiation protocol with a server device for the network;and using an authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, the authorization code having been provided from the client device to the server device via an out-of-band communication channel different from the network, the authorization code corresponding to the client device, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  3. 17
    Broadest claimClaim Score 53, average(NHIP)A method of enabling a client device to connect to a network, the method comprising:receiving, from the client device, an authorization code via an out-of-band communication channel different from the network, the authorization code corresponding to the client device;and after detecting initiation of a security negotiation protocol by the client device, using the authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  4. 18
    A non-transitory computer readable storage medium comprising computer executable instructions for enabling a client device to connect to a network, the computer executable instructions comprising instructions for:obtaining, at a server device and from the client device, an authorization code via an out-of-band communication channel different from the network, the authorization code corresponding to the client device;and after detecting initiation of a security negotiation protocol by the client device, using the authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  5. 19
    A non-transitory computer readable storage medium comprising computer executable instructions for connecting a client device to a network, the computer executable instructions comprising instructions for:initiating, at the client device, a security negotiation protocol with a server device for the network;and using an authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, the authorization code having been provided from the client device to the server device via an out-of-band communication channel different from the network, the authorization code corresponding to the client device, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  6. 20
    A non-transitory computer readable storage medium comprising computer executable instructions for enabling a client device to connect to a network, the computer executable instructions comprising instructions for:receiving, from the client device, an authorization code to the client device via an out-of-band communication channel different from the network, the authorization code corresponding to the client device;and after detecting initiation of a security negotiation protocol by the client device, using the authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  7. 21
    A server device comprising a processor, and a memory, the memory comprising computer executable instructions for enabling a client device to connect to a network by operating the processor to:obtain, from the client device, an authorization code via an out-of-band communication channel different from the network, the authorization code corresponding to the client device;and after detecting initiation of a security negotiation protocol by the client device, use the authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  8. 22
    A server device comprising a processor, and a memory, the memory comprising computer executable instructions for enabling a client device to connect to a network by operating the processor to:receive an authorization code from the client device via an out-of-band communication channel different from the network, the authorization code corresponding to the client device;and after detecting initiation of a security negotiation protocol by the client device, use the authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.
  9. 23
    A client device comprising a processor, and a memory, the memory comprising computer executable instructions for connecting to a network by operating the processor to:initiate, at the client device, a security negotiation protocol with a server device for the network;and use an authorization code in at least one cryptographic operation during establishment of a transport layer security (TLS) session by modifying the security negotiation protocol to utilize the authorization code, the authorization code having been provided from the client device to the server device via an out-of-band communication channel different from the network, the authorization code corresponding to the client device, wherein the authorization code is used in generating at least one of a master secret, a key block, and a pre master secret generated during establishment of the TLS session and the authorization code is used in establishing the TLS session by: obtaining a negotiated secret elliptic curve point;multiplying the elliptic curve point by the authorization code to obtain a product;and forming the pre master secret from an x-coordinate of the product.